Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ban
New Contributor

Adding HA Cluster to FortiAnalyzer

Could you provide me with a little guidance please.

 

I have two new FortiGate 300D devices, running firmware v5.4.  The two devices are part of a HA cluster.

I also have a FortiAnalyzer running firmware v5.4.1.

 

What process do I following to add the FortiGate devices to the FortiAnalyzer.

 

1. Add each of the FortiGate devices individually, to the FortiAnalyzer by specifying their management interface IP addresses?

 

OR

 

1. Add the FortiGate device, that is acting as the master in the HA cluster, specifying the cluster interface IP address

2. Edit the device and check "HA Cluster"

3. Add the second device

 

OR do i do something else.

 

Many thanks.

9 REPLIES 9
aagrafi
Contributor II

You must click the "HA cluster" option in the Add Device wizard. Then you must enter all the SN of the devices in the cluster. Have in mind that all cluster members generate logs, but only the primary device sends the logs to the FAZ. All the other cluster members send their logs to the primary.

Ban
New Contributor

Okay, thanks.  When adding the primary device to the FortiAnalyzer, do I specify the IP address of the cluster interface rather than the IP address of the management interface

aagrafi
Contributor II

It is a good practice to reserve a management port for each Fortigate, so that you can manage each cluster member separately. Having said that, you may use any other IP address of a cluster interface which is reachable by the FAZ. Some people prefer using a loopback address for that.

Ban
New Contributor

Apologies, I think you may have misunderstood.

 

I have a management interface configured on each of the devices, for the reasons you specify above.

 

However, when adding the device to the FortiAnalyzer, I must specify one of the IP addresses that is common to both devices.  For example  the IP address of port1, which will be the same regardless of which device is in control of the cluster.  Is this correct?

aagrafi
Contributor II

As I said, you may use any interfaces's IP address that suits you. The only requirement is that the FAZ must have access to this IP address.

Ban
New Contributor

Would I be correct in thinking that if I specified the management IP address of the primary device and a failover occurred, the FortiAnalyzer would no longer receive alerts because the IP address is no longer in use?

AtiT
Valued Contributor

Hi,

If I remember correctly the IP addresss does not matter. The serial number has to be configured on the FAZ and set it as a HA cluster.

 

What if someone will have an office and the IP address is assigned dynamically to Fortigate. The addresss changes - it should logging in this case also.

 

Is it a problem to arrange a 15min maintenance window and check what happens?

AtiT

AtiT
AtiT
Valued Contributor

I just made some test (FAZ 5.2.8) and I added the device with the IP address 1.1.1.1 to the FAZ.

After I received the first log the IP address changed to the WAN IP.

 

I think it should work.

 

AtiT

AtiT
aagrafi
Contributor II

Yes, this is correct in the case that the other cluster members have different IP address in their management port.

In FortiGates with two management ports, you may use one port for the cluster management and keep the other for management access to each FortiGate individually.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors